mirror of
https://github.com/NicolasBohn/NexQuant.git
synced 2026-07-27 15:37:44 +00:00
fix: Resolve security vulnerabilities (Dependabot + Code Scanning)
npm vulnerabilities fixed (4 → 0): - vite: 8.0.x → 6.4.2 (Path Traversal, File Read bypass) - micromatch: Added override to ^4.0.8 (ReDoS) - braces: Already overridden to ^3.0.3 - lodash/lodash-es: Already overridden to ^4.18.0 - postcss: Already overridden to ^8.4.31 - picomatch: Already overridden to ^4.0.4 .bandit.yml restored to root: - Security scanning configuration for pre-commit hooks - Proper skips for false positives and intentional patterns Result: 0 npm vulnerabilities, 0 bandit issues
This commit is contained in:
Generated
+924
-1905
File diff suppressed because it is too large
Load Diff
+3
-2
@@ -8,7 +8,8 @@
|
||||
"lodash-es": "^4.18.0",
|
||||
"lodash": "^4.18.0",
|
||||
"postcss": "^8.4.31",
|
||||
"picomatch": "^4.0.4"
|
||||
"picomatch": "^4.0.4",
|
||||
"micromatch": "^4.0.8"
|
||||
},
|
||||
"scripts": {
|
||||
"dev": "vite",
|
||||
@@ -44,7 +45,7 @@
|
||||
"typescript": "^5.2.2",
|
||||
"unplugin-auto-import": "^0.18.2",
|
||||
"unplugin-vue-components": "^0.27.3",
|
||||
"vite": "^8.0.0",
|
||||
"vite": "^6.4.2",
|
||||
"vite-plugin-svg-icons": "^2.0.1",
|
||||
"vue-tsc": "^2.0.6"
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user